5.3 Disallow JavaScript's Ability to Hide the Address Bar

Information

The Address Bar shows the current URL, which can be used to identify the website.
Some malicious websites can use JavaScript to hide the address bar so that a user cannot determine the URL.

Solution

Perform the following procedure:

* Open the mozilla.cfg file in the installation directory with a text editor

* Add the following lines to mozilla.cfg:

lockPref("dom.disable_window_open_feature.location", true);

See Also

https://workbench.cisecurity.org/files/1158

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a.

Plugin: Unix

Control ID: af02943156abec6cf73020eed0680ee8e2c73a5612da435349888e01c91a4fef